The flaw is in AsyncSafeTransport at mealie/pkgs/safehttp/transport.py. For a user-controlled hostname, the transport resolves the hostname once and checks the resulting IP against private-range blocking rules. The subsequent HTTP request still uses the original hostname, allowing the underlying async transport to resolve it again instead of pinning the connection to the validated IP. A DNS-rebinding attacker can return a public address during validation and an internal or metadata address during the actual connection, bypassing the SSRF guard. The GitHub Advisory Database states that the path is reachable by authenticated users through /api/recipes/create/url, /api/recipes/test-scrape-url, and /api/recipes/{slug}/image, and that fetched content is reflected back to the requester. The available sources do not fully document the DNS timing and network conditions required to control both resolutions.